Best of · Communication
Best mailbox access APIs for AI agents
All 9 ranked mailbox access APIs on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.
- 9 ranked
- 3 agent-ready
- 5 hosted endpoints
- Updated 9 October 2026
Top three
Picks by need
Worked out from the scores, prices and facts, so they change when the research does.
Transparency & trust
Gmail API BB
82/100 on transparency & trust, against 81 for the overall leader.
Self-hosting under an open licence
EmailEngine BB
self-hosted, Source available under the EmailEngine licence agreement licence.
The shortlist
| # | Tool | Grade | Best for | Price | Where |
|---|---|---|---|---|---|
| 1 | Nylas Email API Nylas |
A 78.7 | Products that act in their users' own mailboxes across several providers and want one schema, webhooks and OAuth handled. | $15 / mo | hosted |
| 2 | Gmail API |
BB 77.8 | An agent working in a Gmail or Google Workspace user's own mailbox, with search, threads, drafts, labels and incremental sync at no per-account fee. | Free | hosted |
| 3 | EmailEngine Postal Systems OÜ |
BB 71.4 | A team that must keep mailbox access on its own infrastructure, has many mailboxes across Gmail, Microsoft 365 and IMAP, and can run a server and Redis. | $120.83 / mo | local |
| 4 | Outlook Mail (Microsoft Graph) Microsoft |
B 66.3 | Agents working in Microsoft 365 or Outlook.com mailboxes that need scoped reading, drafting, sending and incremental sync. | Your plan | hosted |
| 5 | Himalaya Pimalaya |
B 64.5 | An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary. | Free · OSS | local |
| 6 | Unipile UNIPILE SAS |
C 58.4 | A product that needs one API over Gmail, Outlook and IMAP together with LinkedIn or WhatsApp messaging, priced per account. | $55 / mo | hosted |
| 7 | Fastmail API (JMAP) Fastmail Pty Ltd |
C 54.1 | An agent working in its owner's own Fastmail mailbox, where JMAP gives batched reads, structured search and state-based sync on an open standard, and MCP gives a ready connection with read, write and send levels. | $6 / mo | local |
| 8 | Zoho Mail API Zoho |
D 53.8 | An agent working inside its owner's Zoho Mail mailbox or administering a Zoho Mail organisation, where narrow scopes and the MCP server keep access small. | $1 / seat-mo | local |
| 9 | Aurinko Email API Yoxel, Inc. |
E 44.2 | A product that connects many users' Gmail and Microsoft mailboxes and wants one schema, delta sync, tracking and webhooks at a low price per account. | Paid | hosted |
How to choose
- Scopes for read, draft and sendCheck whether reading, drafting and sending need separate scopes, since an agent that only drafts replies should not be able to send mail on the person's behalf.
- Search filters and thread readsCheck how search filters by sender, date and label, and whether a whole thread returns in one call, since one-by-one reads use up limits.
- Sync delay and new-mail eventsCheck how long new mail takes to appear and whether an event is pushed on arrival, since polling for new mail uses up limit calls.
- Send limits and sending addressCheck the send limit and the address mail is sent from, since a cap reached mid-task can leave a reply unsent.
How the benchmark tests this category. One test mailbox with the same two hundred messages on each provider. The same tasks run through each listing's API (search, read a thread, write a draft reply, send, label and archive, receive a new-mail event). We check scopes, sync delay and limits. In this run listings are graded from public evidence against the published checklist.
Each one in detail
Nylas Email API
A 78.7/100Unified email API from Nylas for reading, searching, drafting and sending mail in a person's existing Gmail, Microsoft 365, Exchange, Yahoo, iCloud or IMAP mailbox, with webhooks for new mail. A hosted MCP server exposes the same data.
Verdict One REST schema covers Gmail, Microsoft 365, Exchange, Yahoo, iCloud and IMAP, and IAM API keys launched on 6 October 2026 can be bound to a single mailbox with chosen permissions. The status page lists eight email incidents between 24 July and 17 September 2026, most on IMAP sync and webhooks.
Choose it for Products that act in their users' own mailboxes across several providers and want one schema, webhooks and OAuth handled.
Strengths
- One schema for messages, threads, drafts, folders and attachments across Gmail, Microsoft 365, Exchange EWS, Yahoo, iCloud and IMAP
- IAM API keys bound to one grant, workspace or application with chosen permissions, and 400 days of access activity
Idempotency-Keyheader on send, with documented 409 and 429 replay behaviour
Weaknesses
- Eight status incidents on email between 24 July and 17 September 2026, including about six hours of IMAP retrieval and webhook degradation on 10 September
- IAM principals and keys are managed only in the Dashboard, with no public API or CLI
- On Google and Microsoft,
search_query_nativecombines only within,limitandpage_token
Price $15 / moAuth OAuth or keyx402 nohosted
Gmail API
BB 77.8/100Google's REST API for Gmail mailboxes. It searches and reads messages and threads, writes drafts, sends mail, manages labels and settings, and reports mailbox changes through history records and Cloud Pub/Sub push notifications. Access is by OAuth 2.0.
Verdict Fourteen OAuth scopes separate labels, sending, metadata and read-only access, and the quota page gives every method a unit cost. Eight of the scopes are restricted, read-only and metadata among them, so a public app that reads mail needs Google's verification and an annual third-party security assessment. Gmail mailboxes only.
Choose it for An agent working in a Gmail or Google Workspace user's own mailbox, with search, threads, drafts, labels and incremental sync at no per-account fee.
Strengths
- 14 OAuth scopes, with
gmail.labelsnon-sensitive,gmail.sendsensitive and permanent delete reserved for the fullhttps://mail.google.com/scope - Quota published per method, 5 units for
messages.list, 20 formessages.getand 100 formessages.send, against 6,000 units a minute per user history.listand Pub/Sub push notifications give incremental sync from a storedhistoryId
Weaknesses
- Eight restricted scopes, including
gmail.readonlyandgmail.metadata, need restricted-scope verification for a public app - An app that stores or transmits restricted data on servers needs a security assessment by a Google-approved assessor every 12 months
- No idempotency key on
messages.send, and the error guide says a 200 response doesn't confirm the mail was sent
Price FreeAuth OAuthx402 nohosted
EmailEngine
BB 71.4/100EmailEngine is self-hosted software from Postal Systems that puts one REST API over Gmail, Microsoft 365 and IMAP mailboxes, with webhooks for new mail and a beta MCP server. The owner runs it with Redis.
Verdict A self-hosted REST API over Gmail, Microsoft 365 and IMAP, with a public OpenAPI 3.0 spec and tokens that can be bound to one account, limited by action and group, and rate limited. It needs a server, Redis and a $1,450 yearly licence after a 14-day trial, and the MCP endpoint is a beta, off by default.
Choose it for A team that must keep mailbox access on its own infrastructure, has many mailboxes across Gmail, Microsoft 365 and IMAP, and can run a server and Redis.
Strengths
- Public OpenAPI 3.0 spec for version 2.82.2 with 82 operations, plus llms.txt on both sites and a capabilities.json manifest
- Tokens can be bound to one account, narrowed by action and group, limited by IP range, expiry and rate, and are stored only as SHA-256 hashes
- Idempotency-Key header on both send routes, and 429 responses carry Retry-After and a ttl field
Weaknesses
- Not open source. Running it beyond the 14-day trial needs a subscription at $1,450 or EUR 1,200 a year
- The owner has to run a server and Redis. There is no hosted service, status page or SLA
- The MCP endpoint is labelled beta, is off by default, and its tool set may change between releases
Price $120.83 / moAuth API keyx402 nolocal
Outlook Mail (Microsoft Graph)
B 66.3/100Mail endpoints of Microsoft Graph for Outlook, Microsoft 365 and Exchange Online mailboxes. An app reads, searches, drafts, sends and files messages over REST with OAuth tokens from Microsoft Entra ID.
Verdict Delegated permissions split reading without bodies (Mail.ReadBasic), full reading, writing and sending, and delta queries and change notifications keep a local copy in step. sendMail takes no idempotency key and returns 202 before delivery, and each app is held to four concurrent requests per mailbox.
Choose it for Agents working in Microsoft 365 or Outlook.com mailboxes that need scoped reading, drafting, sending and incremental sync.
Strengths
- Mail.ReadBasic reads messages without body, preview or attachments, and Mail.Send is separate from Mail.ReadWrite
- Delta queries per folder and change notifications with
missedandsubscriptionRemovedlifecycle events $select,$top(1 to 1,000, default 10),bodyPreviewandPrefer: outlook.body-content-type="text"keep responses small
Weaknesses
- sendMail has no idempotency key and answers 202 Accepted before delivery, so a retried send can go out twice
- Four concurrent requests and 10,000 requests per 10 minutes for each app and mailbox pair
- No prompt-injection guidance found in the mail reference or the Mail MCP reference, though message bodies come from outside senders
Price Your planAuth OAuthx402 nohosted
Himalaya
B 64.5/100Himalaya is an open-source command-line email client from the Pimalaya project. It lists, searches, reads, composes and sends mail over IMAP, SMTP, JMAP, the Gmail API, Microsoft Graph and local stores, with JSON output for scripts and agents.
Verdict One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and --json output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026.
Choose it for An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.
Strengths
- Shared commands for mailboxes, envelopes, flags, messages and attachments run the same way over IMAP, JMAP, Gmail, Microsoft Graph, Maildir and mbox
himalaya json-schemaprints a JSON Schema for the--jsonoutput of 90 commands, andmessage read --jsonreturns one designed view on every backend- Secrets come from a shell command such as
pass show, so a password or token need not sit in the config file
Weaknesses
- Until 2.2.1 of 2 October 2026,
message sendtransmitted theBcc:header to every recipient over SMTP (issue #747, reported 12 September 2026) - No read-only mode, no confirmation before a send or delete, and no idempotency key on send were found
- SECURITY.md sends vulnerability reports to the public issue tracker. No security.txt, private reporting route or published advisory was found
Price Free · OSSAuth OAuth or keyx402 nolocal
Unipile
C 58.4/100Unipile is a hosted API from Unipile SAS in France that connects to accounts people already have. It reads, searches, sends and files mail in Gmail, Outlook and IMAP mailboxes, and also covers calendars, LinkedIn, WhatsApp, Instagram and Telegram.
Verdict One REST API covers Gmail, Outlook and IMAP with search, drafts, send with an idempotency key and new-mail webhooks, and the OpenAPI spec is public. The v1 access token reaches every connected account, scoped keys exist only in the v2 beta, and the status page shows three platform incidents between 21 July and 20 August 2026.
Choose it for A product that needs one API over Gmail, Outlook and IMAP together with LinkedIn or WhatsApp messaging, priced per account.
Strengths
- Public OpenAPI 3.0 spec with 94 operations, readable without a key, plus llms.txt and a Markdown copy of every docs page
POST /api/v1/emailsaccepts anIdempotency-Keyheader of up to 255 characters, so a retried send returns the first resultGET /api/v1/emailshas cursor pagination,limitup to 250,meta_only, a full-textsearchand filters for folder, sender, recipient and date
Weaknesses
- A v1 access token reaches every connected account. Scoped keys, documented rate limits and
retry-afterexist only in the v2 beta - status.unipile.com shows platform incidents on 21 July, 30 July and 20 August 2026, the last an API node unavailable for 70 minutes
- The v1 Node SDK on npm is 1.9.3 from 21 May 2025. The newer Node and Python SDKs work only with the v2 beta
Price $55 / moAuth API keyx402 nohosted
Fastmail API (JMAP)
C 54.1/100Fastmail is a paid email, calendar and contacts host from Fastmail Pty Ltd in Melbourne. Agents reach a customer's mailbox through JMAP at api.fastmail.com, the open IETF protocol, or through the company's own MCP server.
Verdict A mailbox API built on the open JMAP standard, with read-only tokens, six OAuth scopes and an MCP server that separates read, write and send access. Fastmail publishes no OpenAPI file, SDK, API changelog, request rate limit or SLA, and its customer terms forbid programmatically generated email to addresses outside the account.
Choose it for An agent working in its owner's own Fastmail mailbox, where JMAP gives batched reads, structured search and state-based sync on an open standard, and MCP gives a ready connection with read, write and send levels.
Strengths
- JMAP is an IETF standard (RFC 8620, 8621 and 9610), so requests, types and errors are specified in public and not tied to one vendor
- API tokens can be read-only or limited to mail, sending, contacts or Masked Email, and are revocable in settings
- OAuth 2.0 requires PKCE with S256, rotates refresh tokens on every use and revokes the grant if an old one is replayed
Weaknesses
- The customer terms forbid programmatically generated email to addresses outside the account, and say the service is not for machine-to-machine workflows
- No OpenAPI file, llms.txt, official SDK or API changelog. The developer page points to the RFCs and four sample scripts
- No request rate limit, Retry-After guidance or SLA was found, and the API terms allow backwards-incompatible changes with notice only promised as an attempt
Price $6 / moAuth OAuth or keyx402 nolocal
Zoho Mail API
D 53.8/100Zoho Mail is Zoho's hosted business email service. Its REST API lets an application read, search, send and organise mail in a Zoho Mail account and administer an organisation's users, domains, groups and policies, with OAuth 2.0 access.
Verdict A REST API over a Zoho Mail mailbox with OAuth scopes that narrow to one resource and one operation, plus an MCP server launched in 2026. Zoho publishes no OpenAPI file, SDK, request rate limit or API changelog, and its usage policy bars automated email.
Choose it for An agent working inside its owner's Zoho Mail mailbox or administering a Zoho Mail organisation, where narrow scopes and the MCP server keep access small.
Strengths
- OAuth scopes name one resource and one operation, such as
ZohoMail.messages.READ, so an agent can hold read access without send or delete. - Every reference page has a Markdown twin, indexed in
https://www.zoho.com/mail/help/llms.txt, with a curl sample and a sample response. - Zoho Mail MCP exposes the API methods as tools on a remote server, and the owner picks which tools a server carries.
Weaknesses
- The Zoho Mail usage policy, updated 2 September 2026, lists automated, bulk and transactional emails among uses that are not allowed.
- No OpenAPI file, official REST SDK or dated API changelog was found. The path carries no version.
- The getting started guide says each API has its own rate limit and gives no numbers. The response code list has no 429.
Price $1 / seat-moAuth OAuthx402 nolocal
Aurinko Email API
E 44.2/100Unified email REST API from Yoxel, Inc. It reads, searches, drafts and sends mail in a user's own mailbox on Gmail, Office 365, Outlook.com, Exchange, Zoho Mail, iCloud and IMAP, with delta sync, open and reply tracking and webhooks.
Verdict One REST interface covers message search with 17 query operators, drafts, sending, folders and delta sync across seven mailbox types, at $1.50 an active account a month and with send-only and read-only scopes. No status page, SLA, changelog, idempotency key on send or official SDK was found, and SOC 2 is not yet held.
Choose it for A product that connects many users' Gmail and Microsoft mailboxes and wants one schema, delta sync, tracking and webhooks at a low price per account.
Strengths
- Public OpenAPI 3.0 description at
apirefs.aurinko.io/assets/swagger.json, with 43 email operations, 34 of them carrying a cURL sample - Four mail scopes.
Mail.Readallows no writes,Mail.Sendallows sending with no read access, andMail.ReadWriteexcludes send - The
qparameter takes 17 search operators, with a table in the docs saying where IMAP and Exchange support is partial
Weaknesses
- No status page, incident history or SLA found, and the terms supply the service as is
- No idempotency key on
POST /v1/email/messages, so a retried send can deliver twice - No changelog, deprecation policy or official SDK found in the docs or on the site
Price PaidAuth OAuthx402 nohosted
Head to head
- Gmail API vs Nylas Email API BB 77.8 vs A 78.7
- EmailEngine vs Nylas Email API BB 71.4 vs A 78.7
- Nylas Email API vs Outlook Mail (Microsoft Graph) A 78.7 vs B 66.3
- Himalaya vs Nylas Email API B 64.5 vs A 78.7
- EmailEngine vs Gmail API BB 71.4 vs BB 77.8
- Gmail API vs Outlook Mail (Microsoft Graph) BB 77.8 vs B 66.3
- Gmail API vs Himalaya BB 77.8 vs B 64.5
- EmailEngine vs Outlook Mail (Microsoft Graph) BB 71.4 vs B 66.3
- EmailEngine vs Himalaya BB 71.4 vs B 64.5
- Himalaya vs Outlook Mail (Microsoft Graph) B 64.5 vs B 66.3
Questions
What are the highest-rated mailbox access APIs for AI agents?
Nylas Email API has the highest benchmark score of the 9 ranked mailbox access APIs, 78.7 (A). Gmail API is second with 77.8 (BB).
How many mailbox access APIs are agent-ready?
3 of the 9 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.
Which mailbox access APIs accept x402 payments?
None of the ranked listings here accepts x402 for its main call yet.
How is this list ranked?
By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026.
How this list is made
The order is the Anchor benchmark score, the same number as on each listing and in the top list. Each listing is graded from public evidence against the benchmark checklist, and the picks above are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.
Full ranked table · 36 head-to-head comparisons · Best tools in every category